European Union Artificial Intelligence Act
The EU AI Act sets risk-based obligations for AI providers and deployers. Application depends on the system, role and provision-specific timetable.
- European Union
- Law
- Current
- Regulation entered into force: 2024-08-01
EU-2024-1689-amended-2026Source checked: Resources ↗
Overview
The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. Adopted on 13 June 2024, it establishes harmonised rules for the development, placement on the market, putting into service, and use of AI systems within the European Union.
The Act takes a risk-based approach, categorising AI systems into four tiers: unacceptable risk (banned), high-risk (strictly regulated), limited risk (transparency obligations), and minimal risk (largely unregulated). This tiered framework ensures that the most stringent requirements apply to AI systems that pose the greatest potential harm to health, safety, and fundamental rights.
The regulation applies to providers of AI systems placed on the EU market regardless of whether those providers are established within the EU or in a third country. It also applies to deployers of AI systems located within the EU and to providers and deployers located outside the EU where the output produced by the AI system is used in the EU.
Key innovations include the creation of AI regulatory sandboxes, mandatory conformity assessments for high-risk AI systems, requirements for transparency and human oversight, and the establishment of the European AI Office to coordinate enforcement. The Act also introduces specific rules for general-purpose AI (GPAI) models, including additional obligations for GPAI models with systemic risk.
Penalties for non-compliance are significant: up to €35 million or 7% of global annual turnover for prohibited AI practices, up to €15 million or 3% for violations of other provisions, and up to €7.5 million or 1% for supplying incorrect information. For SMEs and startups, the lower of the two amounts applies.
The EU AI Act represents a paradigm shift in technology regulation, moving from sector-specific rules to a horizontal framework that covers AI across all industries. Compliance professionals must understand that this regulation will have extraterritorial reach similar to GDPR, affecting organisations worldwide that serve the EU market.
The AI Office, the European Artificial Intelligence Board and national competent authorities have distinct implementation and supervisory roles. Identify the authority and procedure relevant to the specific system and obligation.
Risk management, technical documentation, data governance and quality management obligations must be mapped to the applicable provider or deployer role and risk classification. They are not a universal checklist for every organisation using an AI tool.
A fundamental-rights impact assessment is required for particular deployers and high-risk uses under Article 27, subject to its scope and exclusions. Do not assume every high-risk or critical-infrastructure system requires one. Where applicable, it complements rather than replaces a GDPR data protection impact assessment. Check the amended legal text for the relevant deployment.
Key Requirements
Assess prohibited practices under Article 5 and their specific conditions and exceptions.
High-risk AI systems must undergo conformity assessment before market placement
Mandatory risk management system covering the entire AI system lifecycle
Data governance requirements for training, validation, and testing datasets
Technical documentation and record-keeping obligations
Apply Article 50 transparency duties to the relevant provider or deployer, subject to the applicable conditions, exceptions and transition dates.
Human oversight requirements for high-risk AI systems
Accuracy, robustness, and cybersecurity requirements
Quality management system implementation
Registration in EU public database for high-risk AI systems
General-purpose AI model providers must maintain technical documentation and provide information to downstream providers
GPAI models with systemic risk require model evaluations, adversarial testing, and serious incident reporting
Assess machine-readable marking and disclosure duties for synthetic content under Article 50; not every AI-assisted text has the same disclosure obligation.
Fundamental rights impact assessment for certain high-risk deployments
Key Dates & Timeline
European Commission publishes initial proposal
Political agreement reached between EU institutions
European Parliament adopts the AI Act
Council of the EU formally approves
AI Act enters into force
Prohibited AI practices ban applies
Final voluntary GPAI Code of Practice published as a compliance-support tool
Commission publishes guidelines on GPAI provider obligations
GPAI model obligations apply; governance provisions take effect
Commission proposes the AI Omnibus amendments
AI Omnibus amendments enter into force
General application and Article 50 transparency duties, subject to specific transition rules
Annex III high-risk requirements apply under the amended timetable
Requirements for high-risk AI embedded in regulated Annex I products apply
Who It Affects
- AI system providers placing products on the EU market (regardless of location)
- Deployers (users) of AI systems within the EU
- Importers and distributors of AI systems in the EU
- Product manufacturers placing AI-integrated products on the EU market
- Authorised representatives of non-EU providers
- Any organisation whose AI output is used within the EU
Frequently Asked Questions
When does the EU AI Act take full effect?
The Act entered into force on 1 August 2024. Prohibited practices applied from 2 February 2025 and GPAI rules from 2 August 2025. General application, including Article 50, began on 2 August 2026 with specific transitions. Following the AI Omnibus, Annex III high-risk requirements apply from 2 December 2027 and regulated-product requirements from 2 August 2028. Check the provision and any transitional exception.
Does the EU AI Act apply to companies outside the EU?
Yes. The EU AI Act has extraterritorial scope. It applies to any provider placing AI systems on the EU market and any deployer located in the EU, regardless of where the provider is established. It also applies where the AI output is used in the EU.
What are the penalties for non-compliance?
Fines can reach up to €35 million or 7% of global annual turnover for prohibited AI practices, €15 million or 3% for other violations, and €7.5 million or 1% for supplying incorrect information. Lower caps apply to SMEs and startups.
Stay Ahead of AI Regulations
Receive AI regulatory updates to help prepare your next review.